Application of privacy-preserving techniques in operational record linkage centres

Access Status

Authors

Date

Collection

Type

Metadata

Abstract

Record linkage is the process of bringing together data relating to the same individual within and between different datasets. These integrated datasets provide diverse and rich resources for researchers without the cost associated with additional data collection. By their nature, record linkage systems deal with large volumes of data and require complex organizational and technical infrastructure. Bringing together information from different sources often requires many different organizations to collaborate and share data, which presents challenges around data privacy and confidentiality. Various processes and protocols have been developed to protect the privacy of individuals during the record linkage process. These include data governance procedures covering people, processes and information technology, role separation and restricted data flows. Combinations of these are used to mitigate risks to privacy by limiting access to certain information. In addition, privacypreserving record linkage techniques can be utilized to further reduce the risk to privacy, by removing all personal identifying information from linkage protocols. This chapter reviews current practices, processes and developments for maintaining security and privacy as applied in existing record linkage centres. Models for role separation and data flows are outlined and evaluated, and requirements for an effective privacy-preserving record linkage protocol are described.

Background: Probabilistic record linkage is a process used to bring together person-based records from within the same dataset (de-duplication) or from disparate datasets using pairwise comparisons and matching probabilities. ...

Record linkage typically involves the use of dedicated linkage units who are supplied with personally identifying information to determine individuals from within and across datasets. The personally identifying information ...